Denial of Service Vulnerability in Wireshark USB HID Protocol Dissector
CVE-2026-6534

5.5MEDIUM

Key Information:

Vendor

Wireshark

Status
Vendor
CVE Published:
30 April 2026

What is CVE-2026-6534?

The Wireshark USB HID protocol dissector presents a vulnerability that can lead to an infinite loop when processing specific packets. This affects Wireshark versions 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14, potentially causing a denial of service. Attackers exploiting this flaw can overwhelm the application, resulting in interruptions to network traffic analysis and monitoring. Users are advised to upgrade to the latest version of Wireshark, which includes patches for this issue, to ensure uninterrupted service and enhanced security.

Affected Version(s)

Wireshark 4.6.0 < 4.6.5

Wireshark 4.4.0 < 4.4.15

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sharon Brizinov
.